Skip to content

Commit 0474eda

Browse files
[StepSecurity] Apply security best practices
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
1 parent 5405f3b commit 0474eda

File tree

3 files changed

+4
-4
lines changed

3 files changed

+4
-4
lines changed

.github/workflows/build-push.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -40,7 +40,7 @@ jobs:
4040
go-version-file: ${{ matrix.image }}/go.mod
4141

4242
- uses: sigstore/cosign-installer@4959ce089c160fddf62f7b42464195ba1a56d382 # v3.0.2
43-
- uses: ko-build/setup-ko@3aebd0597dc1e9d1a26bcfdb7cbeb19c131d3037 # v0.7
43+
- uses: step-security/setup-ko@3b4d97844e4277c74a9d77ac00052d8ce96580d3 # v0.9.0
4444

4545
- env:
4646
KO_DOCKER_REPO: ghcr.io/chainguard-dev/${{matrix.image}}

.github/workflows/build.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,7 @@ jobs:
3232
with:
3333
go-version-file: ${{ matrix.image }}/go.mod
3434

35-
- uses: ko-build/setup-ko@3aebd0597dc1e9d1a26bcfdb7cbeb19c131d3037 # v0.7
35+
- uses: step-security/setup-ko@3b4d97844e4277c74a9d77ac00052d8ce96580d3 # v0.9.0
3636
- uses: chainguard-dev/actions/setup-registry@3e8a2a226fad9e1ecbf2d359b8a7697554a4ac6d # main
3737

3838
- working-directory: ${{ matrix.image }}

image-mapper/Dockerfile

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
FROM cgr.dev/chainguard/go:latest AS builder
1+
FROM cgr.dev/chainguard/go:latest@sha256:8df9dd7beb988f8f912df54c036ea44e4b11455da5d33e2a4eb2d19de75820c8 AS builder
22

33
WORKDIR /app
44

@@ -11,7 +11,7 @@ COPY cmd cmd
1111

1212
RUN CGO_ENABLED=0 go build -o image-mapper .
1313

14-
FROM cgr.dev/chainguard/static:latest
14+
FROM cgr.dev/chainguard/static:latest@sha256:9cef3c6a78264cb7e25923bf1bf7f39476dccbcc993af9f4ffeb191b77a7951e
1515

1616
COPY --from=builder /app/image-mapper /usr/local/bin/image-mapper
1717

0 commit comments

Comments
 (0)